Support Centre

You have out of 5 free articles left for the month

Signup for a trial to access unlimited content.

Start Trial

Continue reading on DataGuidance with:

Free Member

Limited Articles

Create an account to continue accessing select articles, resources, and guidance notes.

Free Trial

Unlimited Access

Start your free trial to access unlimited articles, resources, guidance notes, and workspaces.

Hamburg: HmbBfDI publishes checklist for using LLM based chatbots

On November 13, 2023, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) published a checklist for the data protection-compliant use of Large Language Models (LLM) based chatbots. In particular, the HmbBfDI highlighted certain data protection risks of LLM and provided 15 aspects in the checklist that should be considered when using LLM-based chatbots, including among others:

  • the formulation of clear internal instructions about when and in what conditions generative artificial intelligence (AI) tools should be used;
  • involvement of a data protection officer (DPO) when creating internal instructions or implementing a use case for the first time and depending on the use case, preparing a data protection impact assessment (DPIA);
  • ensuring no release of personal data in the AI results;
  • if data is used for the chatbot's own purposes, no personal data may be transmitted to the AI;
  • checking results for accuracy and discrimination; and
  • using the option to refuse the use of the chatbot's data for training purposes. 

You can read the press release, only available in German, here.

Feedback